2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-33655MEDIUM6.7When sending malicous data to kernel by ioctl cmd FBIOPUT_VSCREENINFO,kernel will write memory out of bounds.
CVE-2021-46784MEDIUM6.5In Squid 3.x through 3.5.28, 4.x through 4.17, and 5.x before 5.6, due to improper buffer management, a Denial of Servic...
CVE-2021-40149MEDIUM5.9The web server of the E1 Zoom camera through 3.0.0.716 discloses its SSL private key via the root web server directory. ...
CVE-2021-4135MEDIUM5.5A memory leak vulnerability was found in the Linux kernel's eBPF for the Simulated networking device driver in the way u...
CVE-2021-26382MEDIUM4.4An attacker with root account privileges can load any legitimately signed firmware image into the Audio Co-Processor (AC...
CVE-2021-39028MEDIUM5.4IBM Engineering Lifecycle Optimization - Publishing 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to HTTP header i...
CVE-2021-39019MEDIUM6.5IBM Engineering Lifecycle Optimization - Publishing 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could disclose highly sensitiv...
CVE-2021-39018MEDIUM4.3IBM Engineering Lifecycle Optimization - Publishing 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could disclose sensitive infor...
CVE-2021-39017MEDIUM6.5IBM Engineering Lifecycle Optimization - Publishing 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could allow a remote attacker ...
CVE-2021-39016MEDIUM4.3IBM Engineering Lifecycle Optimization - Publishing 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 does not sufficiently monitor ...
CVE-2021-39015MEDIUM5.4IBM Engineering Lifecycle Optimization - Publishing 7.0, 7.0.1, and 7.0.2 is vulnerable to cross-site scripting. This vu...
CVE-2021-46827MEDIUM6.1An issue was discovered in Oxygen XML WebHelp before 22.1 build 2021082006 and 23.x before 23.1 build 2021090310. An XSS...
CVE-2021-39041MEDIUM5.3IBM QRadar SIEM 7.3, 7.4, and 7.5 may be vulnerable to partial denial of service attack, resulting in some protocols not...
CVE-2021-40016MEDIUM6.5Improper permission control vulnerability in the Bluetooth module.Successful exploitation of this vulnerability will aff...
CVE-2021-40013MEDIUM6.5Improper permission control vulnerability in the Bluetooth module.Successful exploitation of this vulnerability will aff...
CVE-2021-41042MEDIUM5.3In Eclipse Lyo versions 1.0.0 to 4.1.0, a TransformerFactory is initialized with the defaults that do not restrict DTD l...
CVE-2021-44791MEDIUM6.1In Apache Druid 0.22.1 and earlier, certain specially-crafted links result in unescaped URL parameters being sent back i...
CVE-2021-3696MEDIUM4.5A heap out-of-bounds write may heppen during the handling of Huffman tables in the PNG reader. This may lead to data cor...
CVE-2021-3695MEDIUM4.5A crafted 16-bit grayscale PNG image may lead to a out-of-bounds write in the heap area. An attacker may take advantage ...
CVE-2021-37839MEDIUM4.3Apache Superset up to 1.5.1 allowed for authenticated users to access metadata information related to datasets they have...
CVE-2021-31679MEDIUM6.5An issue was discovered in PESCMS-V2.3.3. There is a CSRF vulnerability that allows attackers to delete admin and other ...
CVE-2021-31678MEDIUM6.5An issue was discovered in PESCMS-V2.3.3. There is a CSRF vulnerability that can delete import information about a user'...
CVE-2021-31677MEDIUM6.5An issue was discovered in PESCMS-V2.3.3. There is a CSRF vulnerability that can modify admin and other members' passwor...
CVE-2021-31676MEDIUM6.1A reflected XSS was discovered in PESCMS-V2.3.3. When combined with CSRF in the same file, they can cause bigger destruc...
CVE-2021-46687MEDIUM4.9JFrog Artifactory prior to version 7.31.10 and 6.23.38 is vulnerable to Sensitive Data Exposure through the Project Admi...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now